Multi-Layer Passwordless Authentication Across Active Directory Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Operational technology (OT) and industrial control systems (ICS) environments face challenges in securing user access across multiple network layers due to the complexity of managing multiple user identities, password reuse, and susceptibility to replay attacks, which compromise security and management efficiency.

Innovation Solution

Implementing a computer-implemented method that combines multi-factor authentication with pre-configured hidden data in distributed ledgers for passwordless authentication, allowing users to traverse multiple network layers without remembering multiple passwords and eliminating the need for password input across the wire.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple user identities are created across multiple Active Directory servers or domains to grant access to different security zones, then access control capability is improved, but user complexity and management complexity increase

Engineering Contradiction:
Improveaccess control capabilityVSAvoiduser complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication mechanism where a single authentication token can be used across multiple Active Directory servers and security zones. The token-based approach allows one credential to serve multiple functions and access points, eliminating the need for users to manage separate passwords for each domain while maintaining the ability to control access to different security zones.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an authentication token as an intermediary between users and multiple Active Directory servers. Instead of users directly managing multiple credentials, the token acts as a mediator that authenticates users to various domains and security zones, simplifying the authentication process while maintaining comprehensive access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users input passwords across the wire to access accounts, then authentication capability is maintained, but susceptibility to replay attacks increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidreplay attack susceptibility
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the traditional password transmission mechanism with a token-based authentication system. Instead of transmitting passwords across the wire, the system uses authentication tokens that are generated and validated locally, eliminating the vulnerability associated with transmitting password data over networks and thus preventing replay attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements preliminary authentication where authentication tokens are generated in advance and stored securely. These pre-generated tokens are then used for authentication without requiring users to input passwords during the actual access attempt, ensuring that no password transmission occurs across the wire and eliminating replay attack risks.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If similar or the same password is used for multiple accounts to reduce complexity, then ease of operation is improved, but security of resources across multiple layers is reduced

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication mechanism into two distinct parts: a static authentication token that remains the same across multiple domains, and dynamic domain-specific credentials that are generated on-demand. This segmentation allows users to remember a single token while maintaining security through domain-specific validation, preventing the security risks associated with password reuse.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the authentication parameter from passwords to authentication tokens. The token itself remains constant across multiple domains (improving ease of operation), but the authentication process incorporates domain-specific parameters and validation rules (maintaining security). This parameter change resolves the contradiction by decoupling the credential from the domain-specific security requirements.

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If static accounts exist on jump boxes for access control, then access control capability is maintained, but management complexity increases when users change status

Engineering Contradiction:
Improveaccess control capabilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent transitions from static accounts to dynamic authentication. Instead of maintaining fixed user accounts in multiple Active Directory servers, the system dynamically generates and validates authentication tokens. This dynamic approach automatically adapts to user status changes without requiring manual account updates across multiple domains, reducing management complexity while maintaining access control capability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements a feedback mechanism where authentication tokens are validated against current user status information in real-time. When user status changes (such as leaving the enterprise or contract expiration), the system receives feedback about the updated status and automatically adjusts authentication validity, eliminating the need for manual account deletion across multiple Active Directory servers while maintaining proper access control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12413578B1Passwordless authentication across multiple layers and multiple directory services
Publication Date: 2025.09.09 XAGE SECURITY INC
  • US12413578B1 patent drawing
  • US12413578B1 patent drawing
  • US12413578B1 patent drawing

AI summary

In one embodiment, a method includes receiving a first request to access one or more resources in the first network layer. The method may include acquiring first identity information of a first user account specified in the first request. The method may include performing multi-factor authentication of the first user account using the first identity information. In response to authenticating the first user account using the first identity information, the method may include acquiring multiple shares of pre-configured first hidden data from a distributed ledger in the first network layer. The method may include determining a first password from the multiple shares of pre-configured first hidden data and, using the first password, authenticating the first user account to access the one or more resources in the first network layer.